4 ms·
I saw a presentation at a departmental colloquium 3 years ago which demonstrated similar capabilities. The point is, car companies are not responding well to th
by timtadh 11y ago
I saw a presentation at a departmental colloquium 3 years ago which demonstrated similar capabilities. The point is, car companies are not responding well to this threat even though it is well known to them. In such situations it is in the public's best interest that information about the vulnerabilities be widely disseminated in order to keep the general public safe. Those with know how can already exploit these flaws and likely have been for years. The car companies need to act to secure their customer's systems.
- danielweber 11y ago> In such situations it is in the public's best interest that information about the vulnerabilities be widely disseminated This assumes many facts not in evidence. It may, in fact, be the best thing. But security people, as a rule, are strongly biased to love things that increase the social standing of security researchers, and chaos does that. There are other ways of pressuring the car companies. I'd like to see companies failing to fix disclosed security holes in safety critical applications in a certain period of time face monetary damages, even without need to show harm was caused. But lobbying is boring and getting on the top of HN is fun.
- slantyyz 11y ago>> The point is, car companies are not responding well to this threat even though it is well known to them. I think the problem is related to core competencies (sorry to throw in the MBA speak). The old-school car companies are good at making cars, and not secure computer systems. You can likely say the same about the skill sets of the decision-makers running these companies. Many of them just can't wrap their head around security implications, because they don't fully understand them.
- danielweber 11y agoCar companies, possibly more than anyone else in the world, are the home to people who understand how mechanical failure affects lives. The car companies' failure to patch defects ought to have them facing severe fines. In fact, I would support a bounty system of millions of dollars for researchers who can demonstrate 1) finding a flaw, 2) telling the company, and 3) the company not fixing it in X months. All this finances by fines on the car companies. The above facts doesn't mean that what these guys did was okay.
- slantyyz 11y ago>> Car companies, possibly more than anyone else in the world, are the home to people who understand how mechanical failure affects lives. You're completely right, but the key phrase in your sentence is "mechanical failure". I've worked on analytics projects in the automotive industry for analyzing defects before they get into the "campaign" (aka recall) stage. They are incredibly good at that type of analysis. Most mechanical parts "make sense", since they're designed for only a few functions. An Internet connected computer and software, on the other hand, doesn't always make sense to auto execs because they are significantly more complex. As it relates to the article, I wouldn't be surprised if the car's computer system was perceived more as just a part having a particular set of features by Chrysler's top executives than as a computer system requiring the same types of security controls as, say, an ATM would.